Rethinking OT Security: Why an IT-Centric Approach Falls Short

OT security isn't an IT problem, and treating it like one is where most organisations get it wrong.

Speak to an expert
Cybersecurity
Enterprise IT infrastructure alongside industrial production systems, representing secure convergence of IT and operational technology (OT) to protect critical operations.

For decades, operational technology lived in its own world. The systems running factory floors, power grids, and water treatment plants were isolated by design — and that isolation was the security strategy. Nobody outside the building could reach them, so nobody outside the building was the threat.

That world is gone. And in my experience, most security teams haven't caught up with what that actually means.

The convergence happened faster than the mindset changed

IIoT adoption, remote operations, vendor access, cloud connectivity — all of it has quietly connected OT environments to the same internet-facing attack surface that targets every other part of the business. The efficiency gains are real. But so is the exposure.

The biggest risk in OT security isn't a sophisticated attacker. It's a converged network being defended with an unconverged mindset.

What I mean by that: IT security instincts — patch fast, isolate aggressively, prioritise confidentiality — don't translate cleanly into OT environments. When the compromised system controls a production line or a power substation, taking it offline isn't a precaution. It's an operational event. Sometimes a safety one.

Five differences every security leader needs to understand

After more than 25 years delivering OT/IT convergence projects across manufacturing, energy, and critical infrastructure, these are the gaps I see most often:

1. Priority: availability beats confidentiality

In IT, confidentiality comes first. In OT, availability and physical safety are the actual priority. A system going offline can mean a production stoppage or a physical hazard — not just a data risk.

2. Patching: routine vs. high-risk

IT systems follow regular patch cycles. OT equipment often runs on legacy hardware that can't be patched without scheduled downtime — or can't be patched at all without full replacement.

3. Lifespan: years vs. decades

IT hardware refreshes every 3–5 years. OT equipment can remain in operational use for 15–25 years. You're often securing infrastructure that was designed before modern cyber threats existed.

4. Incident response: isolate vs. assess

In IT, isolating a compromised system is the first move. In OT, that same move may require a physical safety assessment first. The wrong response can be more dangerous than the threat itself.

5. Visibility: mature vs. emerging

IT environments generally have solid asset inventory and monitoring. Many OT environments still don't have basic visibility into what's connected to the network — which makes early threat detection significantly harder.

Joeri Barbier, Global Chief Information Security Officer at Getronics quote on OT security thought leadership

The conversation worth having before an incident forces it

Regulation is catching up — NIS2 now explicitly extends security obligations to operators of essential infrastructure. But compliance isn't the reason to act. The reason to act is that the organisations getting this right aren't bolting IT security tools onto OT networks. They're building a converged security strategy from the ground up, one that respects the different failure modes of each environment.

That's a very different starting point — and it requires a very different conversation.

If you're navigating OT/IT convergence, I'd be interested to hear where the hardest gaps have been in your organisation.

Up Next Insights

Related Insights

  • “Everyone is a target when it comes to cybersecurity” – Elena Sanchez Carvajal


  • The Response Phase of Business Continuity Management


  • The 2026 Cyber Threat Outlook for UK Manufacturing